An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS).
2020-03-12T22:15:14.827
2024-11-21T04:30:09.833
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | ≤ 6.0.5 | Yes |
Application | fortinet | fortiweb | ≤ 6.1.1 | Yes |
Application | fortinet | fortiweb | 6.2.0 | Yes |